VORANT. Threat Intelligence Research Sign in Create a free account

CISA adds Apple OOB write flaw to KEV

high vulnerability technology

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CISA added CVE-2026-86950, an actively exploited out-of-bounds write vulnerability in multiple Apple products, to its Known Exploited Vulnerabilities catalog.

CISA has added CVE-2026-86950, described as an Apple Multiple Products Out-of-Bounds Write Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild. No technical details of the exploitation chain, affected specific products/versions, or threat actor attribution were provided in this bulletin.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of KEV-listed vulnerabilities, particularly those on publicly exposed assets that could grant an attacker total control post-exploitation, and to check for prior compromise before patching. While BOD 26-04 legally applies only to FCEB agencies, CISA recommends all organizations adopt the same risk-based prioritization for this and other KEV entries.

Defenders should identify any Apple products in their environment potentially affected by CVE-2026-86950, consult Apple's advisory for patch details and affected version ranges, and apply updates promptly given confirmed active exploitation. Organizations should also review logs for indicators of compromise predating patch deployment, consistent with BOD 26-04 guidance.

Mentioned in this report

Vulnerabilities CVE-2026-86950KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,339 reports from 152 sources, 2,565 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs